AI Agents Banned from Auto-Operating Finance Apps Without Dual Authorization
China's First Financial AI Agent Security Standard Arrives
Imagine handing your phone to a helpful assistant, only to watch it tap through your banking app and move money around. That's the wild west Beijing just decided to tame.
On August 27, the Beijing Financial Technology Industry Alliance released a group standard called Security Requirements for Intelligent Agent Technology in Financial Applications. It's the first of its kind in China, and it draws a clear line in the sand: third-party AI agents cannot use system permissions to automatically read or operate a financial app's interface without the institution's authorization.
What 'Dual Authorization' Actually Means
Industry experts have boiled the requirement down to a simple phrase: dual authorization. An AI agent needs permission from both the user and the financial institution before it can touch your banking app.
That includes any sneaky data grabs through microphones, screen recording, or screen sharing. If an agent wants in, it has to play by the called party's security rules.
The standard was led by the Beijing National Financial Technology Certification Center and developed with heavy hitters — China Post Savings Bank, ICBC, China UnionPay, Bank of China, Communications Bank, and Huaxia Bank — alongside tech giants like Huawei, Ant Group, Volcano Engine, and Tencent Cloud.
It covers five areas: initialization and input, model reasoning and decision-making, identity authentication and operation, data security and privacy protection, and risk control and compliance.

Why This Rule Exists
Back in December 2025, a smartphone with an AI assistant hit the market. Almost immediately, users reported abnormal logins and payment issues across multiple bank apps. By December 6, the assistant had quietly dropped its ability to operate financial apps. At the time, there were no specific rules to stop it.
The problem? Many AI agents don't use official APIs. Instead, they read screens, simulate clicks, and use OCR to recognize text. It's a clever workaround that covers a lot of ground — but it also bypasses permission controls, risk management, and liability boundaries set by app developers. In payments and wealth management, that's a direct threat to user accounts and funds.
Regulators Step In
May 2026 brought joint guidance from the Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology. They called for managing AI agent permissions and behaviors.
By July, a series of national standard technical guidance documents on AI agent interconnection were published, and the State Administration for Market Regulation issued a mandatory national standard plan for Basic Requirements for Intelligent Agent Application Security. On July 15, the Cyberspace Administration announced a new batch of terminal-side generative AI service filings — seven items in total.
Tech Giants Shift Gears
On the terminal side, manufacturers are already adjusting. The common thread: operations now require the app developer's consent.
Take the new generation of Doubao phones. They've changed how they work with super apps like Alibaba and Tencent. No more screen reading or simulated clicks after user authorization. Access only happens if the app itself provides MCP services and allows control.
Jieyue Star STEPX Neo adopted the GUI-MCP protocol too, letting app developers decide what's open.
In June 2026, WeChat, Honor, and other phone makers launched A2A (Agent-to-Agent) assistant capabilities. Users can initiate WeChat calls or send messages via voice assistants — but only because WeChat actively opened API access and connected with the manufacturer's agent. That's a second layer of authorization beyond the user's own.
Even internationally, Google and Samsung took a similar approach on the Galaxy S26 series: system-opened permissions paired with app cooperation.


Key Points
- Dual authorization required: AI agents need both user and financial institution approval to operate finance apps.
- No more screen-reading or simulated clicks: Third-party agents can't bypass official APIs without authorization.
- Who's behind it: Led by Beijing National Financial Technology Certification Center, with banks and tech companies like Huawei, Ant Group, and Tencent Cloud.
- Regulatory momentum: 2026 saw multiple national standards and filings aimed at controlling AI agent permissions.
- Industry shift: Doubao, Jieyue Star, WeChat, Honor, Google, and Samsung are all moving toward app-cooperative models.
Standard Link: Full Text: Beijing Financial Technology Industry Alliance - Group Standard